3 ms·
Reading the article, I kept thinking: "could you defeat this with an iframe?", and indeed: > One of the best methods to protect against these attacks is strict
by PoignardAzur 2mo ago
Reading the article, I kept thinking: "could you defeat this with an iframe?", and indeed:
> One of the best methods to protect against these attacks is strict isolation. If you isolate the email message using sandboxed iframes you restrict the ability to break out of trusted boundaries. If you are not using sandboxed iframes, always be careful when allowing custom attributes and check for HTML/CSS gadgets. Use a strict allow list of characters when validating keywords and names to avoid mutation when using the CSSOM.
iframes should be the first layer of any defense-in-depth against user-submitted content.
- purplemoonx 2mo agoLol, should we go back to browsing "With Frames" or "Without Frames"
- throw1234567891 2mo agoI have my frame buster buster buster buster ready.